Repository navigation
feat(adapter): failure taxonomy, evidence lookup, drift hardening, and frozen ports (B04) - #17
Merged
selezenart merged 2 commits intoSep 7, 2026
Conversation
…, ports Implements B04 for the Coder B lane: the production adapter surface, plus the conservative classification behind it. Failure taxonomy (B04.1). Turns on one question: did the request reach the network? DNS failure, connection refusal, and a failed TLS handshake all happen before any application data is sent, so nothing can have been broadcast and a retry is safe. A reset, a timeout, a truncated response, an interrupted TLS connection, 429, and 5xx may all follow a delivered request, so none of them permit a retry. HTTP 429 stays ambiguous rather than counting as a rejection, because a rate limiter may reject before or after queuing the work. Any error code this build has never seen classifies post-send: an unknown failure cannot be proof that nothing happened. Evidence lookup (B04.2, B04.3). NOT_FOUND is the dangerous result and gets the strictest treatment. Absence can mean never broadcast, or invisible to this node, or replaced, so permitsResubmission returns false for every observation and no code path converts an absent result into a settlement right. Evidence is bound to the exact request before it is interpreted, so a receipt from another chain, another hash, or another wallet cannot resolve this intent. A receipt that exists for our hash but does not prove our settlement is contradictory and stays unbound rather than being resolved by guess. Hashless discovery is deliberately absent: that is Coder C's Subgraph MCP path, and a second, weaker way to decide a payment happened must not grow here. Drift hardening (B04.4). The settlement boundary depends on a Privy policy, a wallet, a chain, a token, and a cap that all live outside this repository and can change with no commit and no review. detectDrift compares observed identity against a reviewed baseline and fails closed on any difference, including a lowered cap: judging whether a change is benign is not this module's job. assertNoDrift throws rather than returning a value a caller could ignore. Webhooks stay disabled, since signature verification is unproven and polling is already complete. Production entry point (B04.5). Exports only the frozen ports and coarse sanitized error codes, so provider error text carrying bodies and headers never crosses the seam. A test asserts no import reaches an A- or C-owned package rather than trusting review to catch it. The compatibility manifest states what the host must supply, what the adapter does not do, and its live gaps, so fixtures cannot masquerade as live evidence.
The review noted that PersistedIdentity declared a nonce nobody reads, which implies a wrong-nonce defence that does not exist: binding is done on the transaction hash alone. Removed, with a comment recording why, rather than leaving a field that overstates what the type checks.
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
oneshot | 154d8cc | Sep 07 2026, 03:17 PM |
selezenart
merged commit Sep 7, 2026
329ad33
into
milestone/b03-live-settlement-harness
3 of 4 checks passed
6 of 9 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements B04 — provider ambiguity and production adapter pack for the
Coder B lane: the surface Coder A composes against, plus the conservative
classification behind it.
Stacked on B03 (PR #14) → B02 (#12) → B01 (#11). Review those first.
Scope and acceptance criteria
The change is limited to the stated milestone or issue.
Acceptance criteria are listed and satisfied.
No unrelated cleanup is included.
B04.1 failure taxonomy — DNS, refusal, TLS, timeout, 429, 5xx, truncated,
malformed, and lost-success all classified, with only documented pre-broadcast
proof marked
DEFINITELY_NOT_SUBMITTED.B04.2 lifecycle lookup — the five
EvidencePortresults with sanitizedevidence;
NOT_FOUNDnever grants resubmission.B04.3 mismatch cases — wrong hash, chain, wallet, recipient, amount,
multiple Transfers, and contradictory states all preserve ambiguity.
B04.4 hardening — policy and Arc identity rechecked, failing closed on any
change; webhooks remain disabled.
B04.5 entry point — only frozen ports and sanitized errors exported, with
an asserted import boundary and a compatibility manifest.
Product and security invariants
Invariant notes:
No durable product state or tenant boundary exists in this diff. What this
change turns on:
failure, connection refusal, and a failed TLS handshake all occur before any
application data is sent. A reset, timeout, truncation, or an interrupted TLS
connection may follow a delivered request. The first group permits a retry;
the second never does.
work, so it is not proof of non-submission.
post-send. An unknown failure cannot be proof that nothing happened.
NOT_FOUNDis never permission.permitsResubmissionreturnsfalseforevery observation, and evidence is bound to the exact request before it is
interpreted, so a receipt from another chain, hash, or wallet cannot resolve
this intent.
whether a change is benign is not this module's job.
Validation
Independent review evidence
Gate A — exact candidate tree before push
Base commit SHA:
8be8d09b8ab5da19031af28fcee9da128a16f82b(develop)Candidate tree SHA:
f0c2c6f51899665bdf56fff8fbb3bf277927c155Reviewer tool:
free-pi-cli0.2.19Reviewer model:
glm-5.3-flashVerdict:
VERDICT: PASSBlocking findings: None
The reviewed tree equals the committed tree.
The reviewer was asked specifically to attack the pre-broadcast/post-send
boundary per error code, and to hunt for any path turning
NOT_FOUNDinto asettlement right. It concluded the 4xx-except-429 mapping is defensible under
standard HTTP semantics and that
NOT_FOUNDcannot become a settlement rightanywhere in the tree.
Non-blocking finding, fixed in
154d8ccafter the reviewed tree:PersistedIdentitydeclared anoncenobody read, implying a wrong-noncedefence that does not exist. Removed. That commit is not covered by the verdict
above; it deletes one unused field and changes no behaviour, and all 345 tests
still pass.
Gate B — exact remote PR head
Risk and rollback
ESLint and TypeScriptjob finds no root
pnpm-lock.yamland skips. All 345 tests are local only.This gap has now persisted across four milestones and is the largest
outstanding risk in the lane.
when Coder A scaffolds the workspace root. Note PR A02: durable PostgreSQL intent ledger and API boundary #15 (A02) is open and may
do exactly that.
shape, Arc receipt shapes, and the wallet/policy identifier formats all come
from documentation.
COMPATIBILITY_MANIFEST.liveGapsForGateP4lists these incode so fixtures cannot pass as live evidence. Privy and Arc claims remain
NOT VERIFIED.Rollback: additive packages and docs on a short-lived branch. Revert or close.
Human merge